JOIN WAITLIST

We know, we know… terms and privacy policies are not exactly beach reading.  The short version: We do not sell your personal data or use it for advertising. The rest is there for transparency, so if you’re curious, you can always take a look.

Corafia, The App: Privacy Policy 

Corafia LLC
Effective Date: 6/18/26
Owner & Business Contact: Corafia LLC
Contact: info@corafia.com


Introduction

This Privacy Policy explains how Corafia LLC (“we,” “our,” or “us”) collects, uses, shares, and protects your information when you use our mobile application and related services (the “Services” or “Application”). By using the Services, you acknowledge that you have read this Privacy Policy. Where required by law, we will obtain your consent before processing certain types of data. The Services are intended for users in the United States. If you access the Services from outside the United States, please be aware that your information may be processed and stored in the United States, where privacy laws may differ from those in your jurisdiction.
Information We Collect
We collect information you provide directly, information generated through your use of the app, and basic technical data collected automatically.
Information You Provide Directly
First Name, Last Name and email address
Account login credentials
Profile information (such as general location voluntarily provided by you, including city, state, and country, or other preferences)
Any content you voluntarily enter into the app
Health & Wellness Data (User Input)
The Services allow you to log and track personal information such as:
Food and beverage intake
Symptoms and body signals
Sleep, movement, and daily habits
Notes, reflections, or personal observations
This information is personal, may relate to your health or well-being, and is treated as sensitive. See the “Health and Sensitive Information” section for more detail.
Subscription and Payment Information
If you subscribe through Apple, your payment is processed entirely by Apple. We do not collect or store your payment card details. We use RevenueCat, Inc. (“RevenueCat”), a third-party subscription management platform, to validate purchase receipts, manage subscription status and entitlements, and keep your subscription status synchronized across your devices. Through this process, RevenueCat receives limited information including your purchase and transaction history (such as the product purchased, price, and renewal date), subscription status, and an app user identifier, which may be an anonymous identifier or one linked to your account. RevenueCat does not have access to your payment card details, which remain handled entirely by Apple. RevenueCat acts as a data processor on our behalf and does not use this information for its own independent purposes, including advertising. For more information about how RevenueCat processes data, see RevenueCat's Privacy Policy at https://www.revenuecat.com/privacy.
Data We Collect Automatically
When you use the Application, the following data is collected automatically:
Device type and operating system
App usage data (features used, session duration, performance metrics)
This data is used for internal analytics, functionality and performance improvement, security, and legal compliance. It is not used for advertising.
Infrastructure-Level Data (Google Firebase)
When the app communicates with our servers, your device’s IP address is transmitted to Google Firebase as part of standard HTTPS network communication. This is an unavoidable aspect of how internet connections work and is not something we collect or control directly. Google Firebase may record IP addresses in infrastructure-level audit and access logs as part of its normal service operation. These logs are maintained by Google on their infrastructure and are automatically deleted after 30 days by default. This data is not stored in your personal account data within our application.
For more information on how Google Firebase handles infrastructure data, please refer to Google’s Privacy Policy at https://policies.google.com/privacy.
Trackers
This Application uses device identifiers and limited analytics technologies (“Trackers”) to collect data about how you use the app. Trackers are used to:
Enable core app functionality 
Monitor app performance and diagnose issues
Understand general usage patterns to improve the experience
We do not use Trackers for targeted advertising or cross-context behavioral advertising. Any analytics tools used operate solely on our behalf for internal purposes. Because we do not track users across third-party apps or websites for advertising purposes, Apple’s App Tracking Transparency framework may not apply to our use of analytics. You may still adjust analytics-related settings through your device’s privacy controls. Note that disabling certain Trackers may affect app functionality.
Do Not Track Signals
The Application does not respond to “Do Not Track” signals or similar browser-based mechanisms.
How We Use Your Information
We use your information as necessary to operate, provide, maintain, improve, and secure the Services, and as otherwise described in this Privacy Policy. This includes:
Providing and maintaining your account
Enabling habit logging and wellness tracking features within the app
Saving and displaying your entries
Improving app functionality and user experience
Contacting you with service-related communications
Responding to support and privacy rights requests
Maintaining security and preventing misuse or fraud
Complying with legal obligations
We do not use your personal information for third-party advertising. We do not use your personal information for automated decision-making that produces legal or similarly significant effects. We will not process your information for purposes that are not reasonably necessary and compatible with those originally disclosed, without your consent. Our use of user content is also subject to the limitations described in our Terms and Conditions, available within the Application.
De-Identified and Aggregated Data
We may create de-identified or aggregated data from personal information collected through the Services. This means information that can no longer reasonably identify you as an individual. We may use such de-identified or aggregated data for purposes including:
improving and developing the Services
understanding general usage patterns
analytics and research
This data does not identify you personally and is not considered personal information to the extent permitted under applicable law. We do not attempt to re-identify de-identified data. We take reasonable measures to ensure that de-identified data cannot be re-associated with an individual.
How We Share Information
We do not sell or share personal information for advertising. We disclose information only to service providers and as described in the limited circumstances below. The limited circumstances in which we disclose information are as follows:
Service Providers
We may share information with trusted third-party providers that help us operate the app, such as:
Cloud hosting and infrastructure providers (e.g, Google Firebase)
Subscription management providers used to validate purchase receipts, manage entitlements, and track subscription status (e.g., RevenueCat)
Analytics tools used solely for app performance monitoring (e.g., Apple Analytics, Firebase Analytics)
Customer support tools (e.g., email-based support platforms)
These providers are contractually required to protect your information and may only process it as necessary for the app to function — not for their own independent purposes. We will update this Policy if our service providers change in a material way.
Legal Requirements
We may disclose information if required by law, court order, or government authority, or where necessary to protect our rights, our users, or the safety of others. Personal data may also be used for legal purposes in connection with the establishment, exercise, or defense of legal claims.
Business Transfers
If our business is sold, merged, or transferred, your information may be part of that transaction. We will notify users within the app or by email at or around the time your information becomes subject to a materially different privacy policy, and will update the effective date of this Policy to reflect the change.
Health and Sensitive Information
Information you choose to enter — such as symptoms, food intake, sleep, and body-related data — may be considered sensitive personal information under applicable law, and we treat it with heightened care. We use this information to provide core app functionality and to improve the Services, as described in this Policy and based on your consent. We do not use sensitive information for advertising and we do not sell it to third parties. We do not use identifiable user content for marketing or commercial exploitation. Corafia LLC is not a healthcare provider, health plan, or healthcare clearinghouse. This app is not subject to HIPAA. Information you enter is not “protected health information” (PHI) under HIPAA. If you have medical concerns, please consult a qualified healthcare professional.
How we obtain your consent: Before you create an account, and before you are able to enter any health or wellness data, you will be presented with an onboarding screen that discloses, among other things, our collection and use of health and wellness data. To proceed, you must separately check three boxes confirming that you (1) agree to our Terms and Conditions, (2) agree to this Privacy Policy, and (3) confirm that you are 18 years of age or older, and then tap "I Agree — Let's Get Started." This affirmative action constitutes your acceptance of this Privacy Policy and our Terms and Conditions in their entirety, and your consent to our processing of health and wellness data for the purposes described in this Policy. 
Withdrawing consent: Because health and wellness data is central to the core functionality of the Services, we are unable to provide the Services without processing this data. If you wish to withdraw your consent, you may do so by deleting your account through the app settings. Your access to the Services will end upon account deletion, as the Services cannot function without this data. Withdrawal does not affect the lawfulness of processing that occurred before deletion.
We process sensitive information only with your consent or as otherwise permitted by law.
Sources of Information
We collect your personal information from the following sources:
Directly from you, when you register, log data, or submit requests through the app
Automatically, when you use the Application (usage data, device info, Trackers)
Third-party service providers that work with us in connection with the Services
Data Retention
We retain your information only for as long as necessary to provide the Services, fulfill the purposes described in this Privacy Policy, and meet our legal obligations.
Account deletion
You can delete your account at any time through the app settings (Settings > Delete Account). Once you submit your request, your account and all associated data — including your profile and all health and wellness entries you have logged — will be permanently deleted within 30 days. If you are unable to access your account, contact us at info@corafia.com and we will process your request within the same timeframe after verifying your identity.
Deleting the app vs. deleting your account
Uninstalling the app from your device does not delete your account or any associated data. Your account and data remain stored on our servers until you actively submit a deletion request. To permanently delete your account and all associated data, you must use the in-app deletion option (Settings > Delete Account) before uninstalling, or contact us at info@corafia.com if you no longer have access to the app.
Note on subscriptions
If you have an active subscription through Apple, deleting your account does not automatically cancel your subscription. You must cancel your subscription separately through your Apple ID settings or the App Store. We do not have the ability to issue refunds directly — all billing and refunds are handled by Apple and are subject to Apple’s terms and conditions. Purchase and subscription status records processed through RevenueCat are retained by RevenueCat in accordance with its own privacy policy and retention practices, in addition to the retention schedule described below.
Retention schedule
Account and profile data: Deleted within 30 days of account deletion
Health and wellness log data :Deleted within 30 days of account deletion
Transaction and subscription records: Up to 7 years, as required by financial and tax law
Security and fraud prevention logs Up: to 2 years to protect the integrity of the Services
Inactive accounts
If your account has had no login activity for 12 consecutive months, we will send a notice to the email address on file 30 days before your account is scheduled for deletion. If you log in before that date, your account will remain active and the inactivity period will reset. If we do not hear from you, your account and all associated data will be permanently deleted at the end of that 30-day notice period. If the notice cannot be delivered to the email address on file, your account will still be deleted on the scheduled date.
How we process deletion requests
Deletion requests submitted through the app are processed within 30 days. Requests submitted by email are processed within 30 days of identity verification. Where applicable law permits an extension, we will complete your request within 45 days and notify you before the original deadline expires. Certain records may be retained beyond these periods where required by law — for example, transaction records retained for tax compliance. Retained records are used only to satisfy the legal obligation that requires their retention and for no other purpose. Once that obligation expires, the records are permanently deleted.
Data Security
We use industry-standard technical and organizational measures to protect your information from unauthorized access, disclosure, modification, or destruction. All data transmitted between the app and our servers is encrypted in transit using TLS (Transport Layer Security). Data is stored at rest using AES-256 encryption managed by Google Firebase and Firestore infrastructure. Access to your data is controlled through Firebase Authentication, which ensures that only authenticated users can access their own data. Subscription and purchase data processed through RevenueCat is stored on RevenueCat's infrastructure (Amazon Web Services, located in the United States) and is subject to RevenueCat's own security safeguards, including SOC 2 Type II certification. In some cases, your data may be accessible to internal personnel or to service providers (such as hosting or IT contractors) acting as authorized data processors under contractual confidentiality obligations. Access to user content is limited to what is reasonably necessary to operate, maintain, and improve the Services, consistent with the restrictions described in our Terms and Conditions, available within the Application.
While we use industry-standard safeguards, no system can be completely secure. In the event of a data breach affecting your personal information, we will notify affected users as required by applicable law. If you have concerns about the security of your data, please contact us.
Your Privacy Rights
Depending on where you live, you may have certain rights regarding your personal information. These include:
Right to Access: Request confirmation of whether we process your personal information and obtain a copy of the categories of information we hold about you. You may submit up to two access requests in any 12-month period.
Right to Correct: Request correction of inaccurate or incomplete information we hold about you. Note that data you have entered directly into the app — such as wellness logs, symptoms, and activity entries — can be corrected at any time within the app itself without submitting a request.
Right to Delete: Request deletion of your personal information, subject to the retention exceptions described in our Data Retention section. The most direct way to exercise this right is through the in-app account deletion option (Settings > Delete Account).
Right to Portability: Request a copy of the personal information you have provided to us, including your logged entries (such as food, symptoms, sleep, activities, and notes). We will deliver this in JSON format within 30 days of a verified request. You may submit up to two portability requests in any 12-month period.
Right to Opt Out of Sale or Sharing: We do not sell your personal information or share it for cross-context behavioral advertising. There is nothing to opt out of.
Right to Non-Discrimination: We will not deny, charge differently for, or provide a different level of service based on your exercise of any privacy right.
To submit a request, contact us at info@corafia.com from the email address associated with your account. We will respond within 45 days. Where permitted by law, we may extend this period by an additional 45 days (90 days total) and will notify you before the original deadline expires. We may request additional information to verify your identity before fulfilling requests. We will not charge a fee unless a request is repetitive or unreasonably burdensome. If we deny a request, we will explain our reasons, including any applicable legal exemptions. You may appeal our decision by contacting us at info@corafia.com with the subject line “Privacy Appeal.” We will review and respond to your appeal within 45 days.
Authorized Agent Requests
California residents and residents of certain other states may designate an authorized agent to submit privacy rights requests on their behalf. To submit a request through an authorized agent:
The agent must provide written proof of authorization (such as a signed permission letter or power of attorney)
We may contact you directly to verify the request
Send authorized agent requests to info@corafia.com with the subject line “Authorized Agent Request”
Additional Rights Under US State Privacy Laws
Residents of certain U.S. states with applicable privacy laws (including California, Virginia, Colorado, Connecticut, and others) may have additional rights under those laws. Where this section conflicts with other provisions, this section controls for residents of states with applicable privacy laws.
California Residents (CCPA/CPRA)
In addition to the rights listed above, California residents have:
The right to opt out of the Sale or Sharing of personal information for cross-context behavioral advertising (we do not engage in these activities)
The right to limit the use or disclosure of Sensitive Personal Information to what is necessary to provide the Services. To exercise this right, contact us at info@corafia.com with the subject line “Limit Use of Sensitive Information.”
California privacy requests will be handled within 45 days as required by CCPA/CPRA, with a possible 45-day extension where permitted.
Other State Residents (Virginia, Colorado, Connecticut, Texas, Oregon, and others)
In addition to the rights listed above, residents of these states have:
The right to opt out of processing of personal information for Targeted Advertising
The right to opt out of profiling that produces legal or similarly significant effects
The right to freely give, deny, or withdraw consent for processing of Sensitive Personal Information
In Maryland, Sensitive Personal Information will only be collected or processed if strictly necessary to provide a product or service you have requested. Maryland residents also have additional rights described in the “Minnesota and Maryland Residents” section below.
Iowa Residents
Iowa’s Consumer Data Protection Act (effective January 1, 2025) requires opt-in consent before processing sensitive personal information. We obtain that consent through the in-app notice and affirmative confirmation described in the “Health and Sensitive Information” section above, before you first enter any health or wellness data. You may withdraw consent at any time by deleting your account through the app settings.
Iowa residents also have the right to opt out of Targeted Advertising.
Utah Residents
In addition to the rights listed above, Utah residents have:
The right to opt out of processing personal information for Targeted Advertising
The right to opt out of processing of Sensitive Personal Information (subject to certain exceptions)
Minnesota and Maryland Residents
In addition to the above, you also have the right to obtain a list of specific third parties to whom we have disclosed your personal information.
Minnesota Residents — Profiling Rights
We do not engage in automated decision-making that produces legal or similarly significant effects. The following rights apply if profiling is ever used in the future:
Question the results of profiling decisions
Be informed of the reason a profiling decision was made
Be informed of actions that could have produced a different outcome
Review personal information used in the profiling
Have inaccurate data corrected and the decision reevaluated
Children’s Privacy
The Services are intended for individuals 18 years of age and older. We do not knowingly collect personal information from anyone under the age of 18. If you believe we have inadvertently collected information from a minor, please contact us immediately at info@corafia.com and we will investigate and delete that individual’s account and associated data within 30 days of becoming aware.
Changes to This Privacy Policy
We may update this Policy from time to time to reflect changes in our practices or applicable law. If we make material changes, we will update the effective date at the top of this Policy and notify users within the app or by email at or around the time the changes take effect. For changes that affect processing based on your consent, we will seek new consent where required. If you do not agree with the revised Policy, you should discontinue use of the Services.
Contact Us
If you have questions, concerns, or requests related to this Privacy Policy, please contact us at:
Corafia LLC
Email: info@corafia.com
489 4th Street, Brooklyn, NY 11215
This Privacy Policy is governed by the laws of the State of New York, consistent with the governing law provisions of our Terms and Conditions.

Definitions and Legal References
Personal Information
Any information that directly, indirectly, or in connection with other information allows for the identification or identifiability of a natural person.
Sensitive Personal Information
Personal Information that is not publicly available and reveals information considered sensitive under applicable privacy law (e.g., health data, precise geolocation, biometrics).
Usage Data
Information collected automatically through the Application, including device identifiers, app usage patterns, time spent, and other interaction data.
Tracker
Device identifiers and analytics technologies used to collect data about how users interact with the Application, for the purpose of maintaining and improving functionality and performance.
Sale
Any exchange of Personal Information to a third party for monetary or other valuable consideration, as defined by applicable US state law. Sharing with service providers under a qualifying written contract does not constitute a Sale.
Sharing
Communicating a consumer’s Personal Information to a third party for cross-context behavioral advertising, as defined by California privacy laws. Sharing with service providers under a qualifying written contract does not constitute Sharing.
Targeted Advertising
Displaying advertisements selected based on Personal Information obtained from a consumer’s activities over time and across nonaffiliated websites or apps, as defined by applicable US state law.
Owner / Business
The entity that determines the purposes and means of processing Personal Information. For this Application, the Owner is Corafia LLC.
Data Processor
A natural or legal person that processes Personal Information on behalf of the Owner (e.g., a cloud hosting provider).
User
The individual using the Application whose Personal Information is being processed.
This Application
The mobile application through which the User’s Personal Information is collected and processed.
Service
The service provided by this Application as described in the applicable terms and on the Application.
Corafia LLC • info@corafia.com
© 2026 Corafia